← Vulnerability feed

Vulnerability record · CVE-2026-61125 · published 21 July 2026

CVE-2026-61125: Oracle e-business suite information exposure vulnerability

Oracle · E Business Suite

Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Configure to Order. While the vulnerability is in Oracle Configure to Order, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configure to Order accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

7.7 CVSS 3.1 High EPSS 0.39% · top 69.2% CWE-200 · Information exposure
7.7CVSS 3.1 base score
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Aug 2026Last modified by NVD

Description

Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Configure to Order. While the vulnerability is in Oracle Configure to Order, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configure to Order accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-61125 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed9.8CVE-2022-21587Oracle E-Business Suite Desktop Integrator unauthenticated file upload RCEOracle Web Applications Desktop Integrator in Oracle E-Business Suite (versions 12.2.3-12.2.11) fails to require authentication for a critical upload…KEVEPSS 98%analysed10.0CVE-2015-4839Oracle e-business suite vulnerabilityUnspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affec…EPSS 3.8%10.0CVE-2015-4798Oracle e-business suite vulnerabilityUnspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affec…EPSS 3.9%10.0CVE-2008-1826Oracle e-business suite vulnerabilityMultiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and attack vectors related to (a) Advanced Pricing, aka…EPSS 2.2%10.0CVE-2008-0340Oracle application server vulnerabilityMultiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote atta…EPSS 2.6%10.0CVE-2008-0343Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and r…EPSS 2.6%10.0CVE-2008-0344Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka …EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2026-61125), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.